AI-Generated Reviews and the FTC Testimonial Rule: What Businesses Risk in 2026
The FTC's rule on consumer reviews and testimonials was written against a world where fabricating social proof took effort — a farm of writers, a marketplace of accounts, a budget. Generative AI removed the cost of every practice the rule prohibits, and it did so inside the ordinary marketing tools businesses already use. Most of the exposure now sits with companies that never decided to fake anything.
The Rule Regulates Attribution, Not Word Processors
The first question every marketing team asks is whether using AI anywhere near a review program is now off-limits. It isn't, and reading the prohibition that way leads to the wrong controls. What the rule targets is a representation to consumers: that a review was written by someone who actually used the product, that the person exists, and that the reviewer had no undisclosed stake in the outcome. AI is a drafting tool. It becomes a legal problem at the moment its output is presented as a person's genuine experience when no such experience occurred.
That framing resolves most of the edge cases teams get stuck on. A verified customer who dictates three sentences into a phone and lets a model tidy the grammar has produced a real review. A support rep who drafts a "representative" testimonial based on a happy call and publishes it under the customer's first name and last initial has produced a fake one, even though the sentiment is accurate and the customer would probably agree with every word. The test is whether the named person authored and experienced what is attributed to them.
Where AI Quietly Crosses the Line in Normal Workflows
The high-risk patterns are rarely a decision to commit fraud. They are automation defaults that nobody flagged as a compliance surface:
Review-request flows that ask "how did we do?" and branch — public review link for high scores, private feedback form for low ones — are gating, and the AI-assisted CX platforms that ship this as a template are the most common source. Homepage testimonial carousels populated from a model prompted to "write five customer quotes in our brand voice" get attributed to plausible-sounding names during design and never get replaced before launch. Review-response tools that offer to "improve" a customer's submitted text before it posts can cross from formatting into authorship. And AI summary widgets that condense a product's reviews will happily produce an upbeat paragraph from a set of inputs the developer filtered to four stars and above.
Insider and Incentivized Reviews Are the Second Half of the Rule
Fabrication gets the attention, but undisclosed material connections generate at least as much routine exposure. Employees, contractors, founders, and their immediate families writing reviews without disclosing the relationship are covered. So are reviews given in exchange for free product, discounts, or entry into a drawing — and conditioning any incentive on the review being positive is its own problem, separate from disclosure. A company can run a legitimate seeding program; it needs a written policy, a disclosure that appears in the review itself rather than in a terms page, and no language anywhere in the ask that implies the reward depends on the sentiment.
Suppression Counts as Manipulation
Businesses that host reviews on their own site have discretion to remove content that is abusive, off-topic, or fake. What they cannot do is use unfounded legal threats, intimidation, or false claims to get a negative review taken down, or configure a system that silently withholds critical reviews from display while publishing favorable ones. AI moderation makes the second failure easy to build by accident: a sentiment-scored queue where anything below a threshold routes to manual review that never happens is, functionally, suppression with a technical explanation.
Review Program Audit Checklist
Run this against your live site, your review platform settings, and any agency contract.
Why Competitors Find This Before Regulators Do
Enforcement is not the only exposure, and for most companies it is not the first one. Fabricated or manipulated reviews are false advertising, which makes them actionable by competitors under unfair-competition law and by platforms under their own seller policies — and a marketplace suspension arrives in days, not the years an agency investigation takes. Review sets generated by a language model also cluster statistically in ways detection vendors sell products to find: similar sentence lengths, shared vocabulary, timing bursts. A business that assumes the risk is a distant regulatory tail is mispricing the near-term commercial one.
Honest social proof still has to be reachable
A review carousel a screen reader can't announce, or star ratings conveyed by color alone, fails the customers most likely to rely on it — and it is the same class of site defect that turns into an accessibility complaint. RatedWithAI scans your pages for the issues that create that exposure.
Scan Your Site for Free →Frequently Asked Questions
Can we use AI to translate a genuine review into another language?
Yes, and translation of a real customer's real review is not fabrication. Keep the original text on file so the source is provable, and avoid letting a translation model soften criticism — a rendering that changes the substance of what the reviewer said stops being a translation and becomes an edit you authored.
What about testimonials in ads that use an actor?
A dramatization performed by an actor is permissible when it is clear to consumers that is what they are watching, and it does not misrepresent the experience of actual customers. AI-generated spokespeople raise the same question with less signal to the viewer, which is why the disclosure needs to be prominent rather than a line in the end card.
We inherited testimonials from an agency and can't verify them. What now?
Take them down while you verify rather than after. Unverifiable testimonials are the cheapest thing on a site to remove and among the most expensive to defend, and continuing to publish them after you have doubts is worse than the original mistake.
Does the rule apply to B2B and SaaS companies, not just ecommerce?
Yes. Nothing in the prohibition is limited to consumer retail, and G2-style software review sites, case-study quotes, and logo-wall attributions are the same representation about a real customer's real experience. B2B teams tend to assume the rule is a marketplace issue and audit accordingly, which is precisely why the exposure sits unexamined.
Do we need to keep records proving reviews are genuine?
There is no prescribed retention format, but the practical defense is documentary: purchase or account records tying a review to a real customer, the unmodified original submission, and disclosure records for any incentivized or insider reviews. Building this while the program runs costs almost nothing; reconstructing it under an inquiry is where the expense lands.